Swiss BIT Breach: What Happened to the Federal IT Agency's SharePoint Servers
An investigation into how threat actors exploited on-premises SharePoint patch latency to compromise 200 Swiss federal government IT accounts.
Switzerland's Federal Office of Information Technology (BIT)—the primary IT backbone for the Swiss federal government—confirmed that attackers exploited unpatched on-premises SharePoint vulnerabilities to compromise approximately 200 user and technical service accounts.
What Happened
On July 28, 2026, BIT automated monitoring detected unusual activity across its internal SharePoint infrastructure. By July 31, forensic analysis confirmed that credentials for roughly 200 accounts had been compromised.
BIT immediately severed internet access to the affected SharePoint environment, applied security updates to close the exploited vectors, and initiated mandatory credential resets across all affected accounts.
Who's Affected
The compromised accounts belonged to BIT personnel and internal service roles responsible for federal IT operations. Swiss authorities stated that the affected server instance was not classified for confidential or top-secret federal data, and initial investigations showed no evidence of secondary data exfiltration beyond the account credentials themselves.
Technical Root Cause: The SharePoint Patch Latency Window
Attackers capitalized on the window between Microsoft's public security patch release and BIT's internal patch deployment cycle. On-premises SharePoint vulnerabilities (particularly deserialization and remote code execution bugs) have repeatedly been weaponized by threat actors within days of public advisory releases.